Prototype Pollution in just-extend
Critical severity
GitHub Reviewed
Published
Feb 7, 2019
to the GitHub Advisory Database
•
Updated Sep 7, 2023
Description
Published to the GitHub Advisory Database
Feb 7, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 7, 2023
Versions of
just-extend
before 4.0.0 are vulnerable to prototype pollution. Provided certain inputjust-extend
can add or modify properties of theObject
prototype. These properties will be present on all objects.Recommendation
Update to version
4.0.0
or later.References